Secure Remote Services

Vendor:

First CVE: Mar 12, 2015 · Active for 11 years

8
Total CVEs
More Total CVEs than 85% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Secure Remote Services over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 12, 2015
11 years ago
Most Recent CVE
Oct 18, 2018
2,837 days ago

CVE Severity & Scoring

Secure Remote Services8 CVEs
All CVEs352,427 CVEs
MediumHigh
Attack Vector
Local2 (25.0%)
Network2 (25.0%)
Unknown4 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (50.0%)
High0 (0.0%)
Unknown4 (50.0%)
User Interaction
None4 (50.0%)
Unknown4 (50.0%)
Required0 (0.0%)
Privileges Required
Low3 (37.5%)
High0 (0.0%)
None1 (12.5%)
Unknown4 (50.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly generate random values for session cookies, which makes it easier for remote attackers to hij
Jul 5, 20159.328NONO
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains Improper File Permission Vulnerabilities. The application contains multiple configuration files with world-r
Oct 18, 20187.824NONO
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored in plaintext in a configuration
Oct 18, 20187.824NONO
The Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary OS commands via unspecified vect
Mar 12, 20157.520NONO
SQL injection vulnerability in the Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary S
Mar 12, 20157.520NONO
EMC ESRS VE 3.18 or earlier contains Authentication Bypass that could potentially be exploited by malicious users to compromise the affected system.
Jun 14, 20175.316NONO
EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof
Jul 5, 20155.816NONO
Directory traversal vulnerability in the API in EMC Secure Remote Services Virtual Edition 3.x before 3.10 allows remote authenticated users to read log files via a crafted paramet
Dec 28, 20154.314NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Secure Remote Services

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.1815.31.8%00
3.0427.51.6%00
3.0356.92.2%00
3.0256.92.2%00
3.014.32.0%00